# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T04:24:46Z", "synthesisSha256": "37006e0c028a3c79628a6b0f85d2a7e6240ea4947b36953ad965940f3321a7f5", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-016", "registryId": "vr.wm-xct-016", "name": "Identity Register", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "registry", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.IDREG" ], "tags": [ "identity", "register", "xct.idreg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-016-identity-register/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-016", "model": { "registry_id": "vr.wm-xct-016", "model_id": "WM-XCT-016", "name": "Identity Register", "entry_kind": "registry", "purpose": "Provide a governed, durable and source-qualified registry pattern for anchoring and resolving identifiers of persons, organizations, devices, services and things without importing their descriptive master data.", "scope_statement": "Owns register and namespace identity, entry anchors, identifier and alias bindings, registration and assignment evidence, assurance, lifecycle, entity-resolution assertions, merge and split lineage, purpose-bound resolution, federation mappings, subject rights, access and retention. Subject profiles, credentials, accounts, authentication factors, keys, authorization decisions, source documents and business lifecycle remain external.", "in_scope": [ "Register authority and profile, namespace, identifier scheme, syntax, canonicalization, comparison, uniqueness, persistence, non-reuse and resolver contract", "Entry identity and external subject reference, identifier bindings, minimal aliases, assignment and proofing evidence, assurance, quality, conflicts, lifecycle and entity resolution", "Federation and loss-aware mappings, purpose-bound projections, privacy, subject rights, access, retention, disposition and safe agent operations" ], "out_of_scope": [ "Person, organization, device, service, thing, credential, account, authentication factor, key, authorization policy, source document or audit-log master lifecycle", "Biometric algorithms, credential issuance, authentication execution, access decisions, universal name authority or copying full subject profiles into the register", "Guarantees of universal identity truth, cross-register equivalence, legal identity, eligibility or rights that are not established by a named authority and jurisdiction" ], "boundary_notes": [ { "neighbor": "Person, Organization, Device, Service or Thing", "distinction": "The register stores a minimal external subject reference and identity assertions; each subject model owns descriptive, physical, functional and contextual properties.", "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011" ] }, { "neighbor": "Credential / Attestation", "distinction": "A credential owns issuer claims and validity; the register may cite it as evidence without becoming its issuer, holder or status list.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "neighbor": "Account / Authentication / Key", "distinction": "An entry or identifier can be linked to an account, authenticator or controlled identifier, but lookup does not prove possession or authorize access.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "neighbor": "Entity Resolution / Master Data", "distinction": "This pattern records identity-specific candidate matches, equivalence and lineage; descriptive golden-record consolidation remains in domain master-data models.", "source_refs": [ "SRC-001", "SRC-006", "SRC-011" ] }, { "neighbor": "Authorization / Decision / Audit Log", "distinction": "Resolution and assurance are evidence for external decisions, while the model keeps identity-specific provenance and delegates generic logging and authorization.", "source_refs": [ "SRC-002", "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Information security, cybersecurity and privacy protection - A framework for identity management - Part 1: Core concepts and terminology", "organization": "International Organization for Standardization and International Electrotechnical Commission", "url": "https://www.iso.org/standard/24760-1?browse=tc", "version_or_date": "ISO/IEC 24760-1:2025, edition 3, September 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines identity-management concepts and distinctions among identity, identity information, identifiers, credentials, attributes, lifecycle, verification, federation and privacy." }, { "id": "SRC-002", "title": "Digital Identity Guidelines", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/800-63-4/sp800-63.html", "version_or_date": "NIST SP 800-63-4, July 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines digital identity roles, proofing, enrollment, authentication and federation assurance while separating these functions and addressing privacy, redress and risk." }, { "id": "SRC-003", "title": "Controlled Identifiers v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/cid-1.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines controlled identifiers, controller documents, verification relationships, services and privacy and correlation risks." }, { "id": "SRC-004", "title": "Decentralized Identifiers (DIDs) v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/did-core/", "version_or_date": "W3C Recommendation, 19 July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines identifier syntax, controller documents, DID methods, resolution, representation and update, deactivation and privacy semantics." }, { "id": "SRC-005", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Separates subjects, issuers, holders, verifiers, credentials and claims and defines validity, status, evidence, privacy and loss-aware transformation expectations." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Provides entities, activities, agents, derivation, attribution and revision relations for identity evidence and registry changes." }, { "id": "SRC-007", "title": "Uniform Resource Identifier (URI): Generic Syntax", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3986", "version_or_date": "RFC 3986, January 2005, updated by RFC 7320 and RFC 8820", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines URI syntax, normalization and comparison and separates identification from access or interaction." }, { "id": "SRC-008", "title": "Universally Unique IDentifiers (UUIDs)", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9562", "version_or_date": "RFC 9562, May 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines UUID format, versions, uniqueness properties and URN representation for local or federated entry identifiers." }, { "id": "SRC-009", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines timestamps with seconds and explicit UTC offset for registration, validity, observation, correction and knowledge events." }, { "id": "SRC-010", "title": "GS1 Digital Link Standard: URI Syntax", "organization": "GS1", "url": "https://ref.gs1.org/standards/digital-link/uri-syntax/1.7.0/", "version_or_date": "Release 1.7.0, ratified August 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Defines governed identifiers for products, assets and locations, compound keys, canonical URI form and resolver-oriented use." }, { "id": "SRC-011", "title": "Supporting Documents for LEI Common Data File Formats", "organization": "Global Legal Entity Identifier Foundation", "url": "https://www.gleif.org/en/lei-data/access-and-use-lei-data/supporting-documents", "version_or_date": "Current versions accessed 6 September 2026", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T04:15:00Z", "relevance": "Provides official schemas for legal-entity identifiers, relationship records, reporting exceptions and legal-entity event history." } ], "structure": { "bundles": [ { "id": "register-authority-namespace-and-scheme", "name": "Register authority, namespace and scheme", "description": "Defines the identity register itself and the governed identifier space it operates.", "rationale": "A register has its own authority and policy; it does not become the subjects it identifies.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-010", "SRC-011" ], "layers": [ { "id": "register-identity-mandate-and-profile", "name": "Register identity, mandate and profile", "description": "Establishes who operates the register, under what mandate and for which subject domain.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ], "findings": [ { "id": "register-identifier-owner-steward-mandate-and-jurisdiction", "name": "Register identifier, owner, steward, mandate and jurisdiction", "description": "Stable register identity, accountable operator, registrar, steward, legal or policy mandate, jurisdiction and authoritative service references.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ], "questions": [ { "id": "register-identifier-owner-steward-mandate-and-jurisdiction-q01", "text": "What identifiers, authorities, classes, versions, scope and values define register identifier, owner, steward, mandate and jurisdiction?", "kind": "identity", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "register-identifier-owner-steward-mandate-and-jurisdiction-q02", "text": "Which source, evidence, event time, effective time and knowledge time support register identifier, owner, steward, mandate and jurisdiction?", "kind": "evidence", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "register-identifier-owner-steward-mandate-and-jurisdiction-q03", "text": "How may register identifier, owner, steward, mandate and jurisdiction be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "register-identifier-owner-steward-mandate-and-jurisdiction-data", "name": "Register identifier, owner, steward, mandate and jurisdiction data", "description": "Structured identity-register data for register identifier, owner, steward, mandate and jurisdiction.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "register-identifier-owner-steward-mandate-and-jurisdiction-record", "name": "Register identifier, owner, steward, mandate and jurisdiction record", "description": "Versioned evidence-bearing registry record for register identifier, owner, steward, mandate and jurisdiction with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register identifier plus register-identifier-owner-steward-mandate-and-jurisdiction assertion or event identifier; no entry segment is required for register-scoped records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "register-profile-subject-domain-authoritative-scope-and-version", "name": "Register profile, subject domain, authoritative scope and version", "description": "Profile identity and version, supported subject kinds, authoritative assertions, exclusions, predecessor and compatibility status.", "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011" ], "questions": [ { "id": "register-profile-subject-domain-authoritative-scope-and-version-q01", "text": "What identifiers, authorities, classes, versions, scope and values define register profile, subject domain, authoritative scope and version?", "kind": "definition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "register-profile-subject-domain-authoritative-scope-and-version-q02", "text": "Which source, evidence, event time, effective time and knowledge time support register profile, subject domain, authoritative scope and version?", "kind": "authority", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "register-profile-subject-domain-authoritative-scope-and-version-q03", "text": "How may register profile, subject domain, authoritative scope and version be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "interoperability", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "register-profile-subject-domain-authoritative-scope-and-version-data", "name": "Register profile, subject domain, authoritative scope and version data", "description": "Structured identity-register data for register profile, subject domain, authoritative scope and version.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "register-profile-subject-domain-authoritative-scope-and-version-record", "name": "Register profile, subject domain, authoritative scope and version record", "description": "Versioned evidence-bearing registry record for register profile, subject domain, authoritative scope and version with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register identifier plus register-profile-subject-domain-authoritative-scope-and-version assertion or event identifier; no entry segment is required for register-scoped records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "namespace-scheme-and-identifier-rules", "name": "Namespace, scheme and identifier rules", "description": "Makes identifier meaning, comparison and persistence explicit.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-008", "SRC-010" ], "findings": [ { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison", "name": "Namespace, scheme authority, syntax, canonical form and comparison", "description": "Namespace and scheme identifiers, naming authority, grammar, character and case rules, canonical form, parser, validator and equality rules.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ], "questions": [ { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison-q01", "text": "What identifiers, authorities, classes, versions, scope and values define namespace, scheme authority, syntax, canonical form and comparison?", "kind": "relationship", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison-q02", "text": "Which source, evidence, event time, effective time and knowledge time support namespace, scheme authority, syntax, canonical form and comparison?", "kind": "temporal", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison-q03", "text": "How may namespace, scheme authority, syntax, canonical form and comparison be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "access", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison-data", "name": "Namespace, scheme authority, syntax, canonical form and comparison data", "description": "Structured identity-register data for namespace, scheme authority, syntax, canonical form and comparison.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "namespace-scheme-authority-syntax-canonical-form-and-comparison-record", "name": "Namespace, scheme authority, syntax, canonical form and comparison record", "description": "Versioned evidence-bearing registry record for namespace, scheme authority, syntax, canonical form and comparison with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register identifier plus namespace-scheme-authority-syntax-canonical-form-and-comparison assertion or event identifier; no entry segment is required for register-scoped records.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy", "name": "Uniqueness scope, persistence, reassignment, reservation and resolution policy", "description": "Uniqueness domain, minting strategy, collision handling, persistence, non-reuse or reassignment rule, reserved ranges and resolver contract.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008", "SRC-010" ], "questions": [ { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy-q01", "text": "What identifiers, authorities, classes, versions, scope and values define uniqueness scope, persistence, reassignment, reservation and resolution policy?", "kind": "requirement", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy-q02", "text": "Which source, evidence, event time, effective time and knowledge time support uniqueness scope, persistence, reassignment, reservation and resolution policy?", "kind": "decision", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy-q03", "text": "How may uniqueness scope, persistence, reassignment, reservation and resolution policy be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "exception", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy-data", "name": "Uniqueness scope, persistence, reassignment, reservation and resolution policy data", "description": "Structured identity-register data for uniqueness scope, persistence, reassignment, reservation and resolution policy.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy-record", "name": "Uniqueness scope, persistence, reassignment, reservation and resolution policy record", "description": "Versioned evidence-bearing registry record for uniqueness scope, persistence, reassignment, reservation and resolution policy with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register identifier plus uniqueness-scope-persistence-reassignment-reservation-and-resolution-policy assertion or event identifier; no entry segment is required for register-scoped records.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "entry-subject-identifiers-and-classification", "name": "Entry, subject, identifiers and classification", "description": "Anchors a minimal registry entry to an external subject and its governed identifiers.", "rationale": "Entry, subject, identifier, name, credential and account remain different entities.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010", "SRC-011" ], "layers": [ { "id": "entry-identity-subject-reference-and-type", "name": "Entry identity, subject reference and type", "description": "Defines the anchor and what kind of subject it denotes without copying the subject profile.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-008", "SRC-011" ], "findings": [ { "id": "entry-id-register-ref-status-created-time-and-head-revision", "name": "Entry ID, register reference, status, created time and head revision", "description": "Register-qualified entry ID, immutable creation event, current derived status, revision head, predecessor and tombstone or redirect state.", "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ], "questions": [ { "id": "entry-id-register-ref-status-created-time-and-head-revision-q01", "text": "What identifiers, authorities, classes, versions, scope and values define entry id, register reference, status, created time and head revision?", "kind": "ownership", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "entry-id-register-ref-status-created-time-and-head-revision-q02", "text": "Which source, evidence, event time, effective time and knowledge time support entry id, register reference, status, created time and head revision?", "kind": "provenance", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "entry-id-register-ref-status-created-time-and-head-revision-q03", "text": "How may entry id, register reference, status, created time and head revision be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "privacy", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "entry-id-register-ref-status-created-time-and-head-revision-data", "name": "Entry ID, register reference, status, created time and head revision data", "description": "Structured identity-register data for entry id, register reference, status, created time and head revision.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "entry-id-register-ref-status-created-time-and-head-revision-record", "name": "Entry ID, register reference, status, created time and head revision record", "description": "Versioned evidence-bearing registry record for entry id, register reference, status, created time and head revision with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus entry-id-register-ref-status-created-time-and-head-revision assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary", "name": "Subject master reference, kind, classification and distinguishing boundary", "description": "External subject master and kind, classification scheme and version, class criteria, part-whole boundary and minimum distinguishing features.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-010", "SRC-011" ], "questions": [ { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary-q01", "text": "What identifiers, authorities, classes, versions, scope and values define subject master reference, kind, classification and distinguishing boundary?", "kind": "classification", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary-q02", "text": "Which source, evidence, event time, effective time and knowledge time support subject master reference, kind, classification and distinguishing boundary?", "kind": "quality", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary-q03", "text": "How may subject master reference, kind, classification and distinguishing boundary be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "security", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary-data", "name": "Subject master reference, kind, classification and distinguishing boundary data", "description": "Structured identity-register data for subject master reference, kind, classification and distinguishing boundary.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "subject-master-reference-kind-classification-and-distinguishing-boundary-record", "name": "Subject master reference, kind, classification and distinguishing boundary record", "description": "Versioned evidence-bearing registry record for subject master reference, kind, classification and distinguishing boundary with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus subject-master-reference-kind-classification-and-distinguishing-boundary assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "identifier-bindings-aliases-and-minimal-labels", "name": "Identifier bindings, aliases and minimal labels", "description": "Records identifiers and discovery aids as evidence-bearing bindings rather than subject truth.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-010" ], "findings": [ { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity", "name": "Identifier binding, scheme, value, canonical value, status and validity", "description": "Binding identity, scheme and namespace, original and canonical value, assignment authority, binding status, valid interval, predecessor and successor.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ], "questions": [ { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity-q01", "text": "What identifiers, authorities, classes, versions, scope and values define identifier binding, scheme, value, canonical value, status and validity?", "kind": "composition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity-q02", "text": "Which source, evidence, event time, effective time and knowledge time support identifier binding, scheme, value, canonical value, status and validity?", "kind": "measurement", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity-q03", "text": "How may identifier binding, scheme, value, canonical value, status and validity be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity-data", "name": "Identifier binding, scheme, value, canonical value, status and validity data", "description": "Structured identity-register data for identifier binding, scheme, value, canonical value, status and validity.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "identifier-binding-scheme-value-canonical-value-status-and-validity-record", "name": "Identifier binding, scheme, value, canonical value, status and validity record", "description": "Versioned evidence-bearing registry record for identifier binding, scheme, value, canonical value, status and validity with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus identifier-binding-scheme-value-canonical-value-status-and-validity assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "alias-name-locator-language-purpose-source-and-disclosure", "name": "Alias, name, locator, language, purpose, source and disclosure", "description": "Typed alias, display label or locator with language, audience, purpose, source, effective interval, sensitivity and explicit non-identity semantics.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "alias-name-locator-language-purpose-source-and-disclosure-q01", "text": "What identifiers, authorities, classes, versions, scope and values define alias, name, locator, language, purpose, source and disclosure?", "kind": "state", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "alias-name-locator-language-purpose-source-and-disclosure-q02", "text": "Which source, evidence, event time, effective time and knowledge time support alias, name, locator, language, purpose, source and disclosure?", "kind": "lifecycle", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "alias-name-locator-language-purpose-source-and-disclosure-q03", "text": "How may alias, name, locator, language, purpose, source and disclosure be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "retention", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "alias-name-locator-language-purpose-source-and-disclosure-data", "name": "Alias, name, locator, language, purpose, source and disclosure data", "description": "Structured identity-register data for alias, name, locator, language, purpose, source and disclosure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "alias-name-locator-language-purpose-source-and-disclosure-record", "name": "Alias, name, locator, language, purpose, source and disclosure record", "description": "Versioned evidence-bearing registry record for alias, name, locator, language, purpose, source and disclosure with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus alias-name-locator-language-purpose-source-and-disclosure assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assignment-proofing-evidence-and-assurance", "name": "Assignment, proofing, evidence and assurance", "description": "Explains why an entry and identifier binding may be relied upon for a stated purpose.", "rationale": "Evidence and assurance are time-, method- and scope-qualified; they never make the registry universally authoritative.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-011" ], "layers": [ { "id": "registration-assignment-and-binding-evidence", "name": "Registration, assignment and binding evidence", "description": "Captures source-qualified evidence and authority for entry creation and identifier binding.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-011" ], "findings": [ { "id": "registration-request-registrar-authority-method-and-decision-evidence", "name": "Registration request, registrar authority, method and decision evidence", "description": "Request identity, applicant or source reference, registrar and delegation, method, policy version, evidence refs, decision, reason and event time.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-009" ], "questions": [ { "id": "registration-request-registrar-authority-method-and-decision-evidence-q01", "text": "What identifiers, authorities, classes, versions, scope and values define registration request, registrar authority, method and decision evidence?", "kind": "identity", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "registration-request-registrar-authority-method-and-decision-evidence-q02", "text": "Which source, evidence, event time, effective time and knowledge time support registration request, registrar authority, method and decision evidence?", "kind": "evidence", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "registration-request-registrar-authority-method-and-decision-evidence-q03", "text": "How may registration request, registrar authority, method and decision evidence be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "registration-request-registrar-authority-method-and-decision-evidence-data", "name": "Registration request, registrar authority, method and decision evidence data", "description": "Structured identity-register data for registration request, registrar authority, method and decision evidence.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "registration-request-registrar-authority-method-and-decision-evidence-record", "name": "Registration request, registrar authority, method and decision evidence record", "description": "Versioned evidence-bearing registry record for registration request, registrar authority, method and decision evidence with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus registration-request-registrar-authority-method-and-decision-evidence assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence", "name": "Identifier assignment, source document, attestation and integrity evidence", "description": "Assignment event, issuing authority, source document or credential reference, attestation, digest, custody, verification result and disclosure marking.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ], "questions": [ { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence-q01", "text": "What identifiers, authorities, classes, versions, scope and values define identifier assignment, source document, attestation and integrity evidence?", "kind": "definition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence-q02", "text": "Which source, evidence, event time, effective time and knowledge time support identifier assignment, source document, attestation and integrity evidence?", "kind": "authority", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence-q03", "text": "How may identifier assignment, source document, attestation and integrity evidence be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "interoperability", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence-data", "name": "Identifier assignment, source document, attestation and integrity evidence data", "description": "Structured identity-register data for identifier assignment, source document, attestation and integrity evidence.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "identifier-assignment-source-document-attestation-and-integrity-evidence-record", "name": "Identifier assignment, source document, attestation and integrity evidence record", "description": "Versioned evidence-bearing registry record for identifier assignment, source document, attestation and integrity evidence with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus identifier-assignment-source-document-attestation-and-integrity-evidence assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "assurance-quality-conflict-and-observation", "name": "Assurance, quality, conflict and observation", "description": "Makes uncertainty and disagreement visible at assertion level.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-009" ], "findings": [ { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment", "name": "Assurance level, basis, scope, confidence, freshness and reassessment", "description": "Named assurance framework and level, assessed assertion, proofing or validation basis, confidence, residual risk, assessment and expiry time.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009" ], "questions": [ { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment-q01", "text": "What identifiers, authorities, classes, versions, scope and values define assurance level, basis, scope, confidence, freshness and reassessment?", "kind": "relationship", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment-q02", "text": "Which source, evidence, event time, effective time and knowledge time support assurance level, basis, scope, confidence, freshness and reassessment?", "kind": "temporal", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment-q03", "text": "How may assurance level, basis, scope, confidence, freshness and reassessment be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "access", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment-data", "name": "Assurance level, basis, scope, confidence, freshness and reassessment data", "description": "Structured identity-register data for assurance level, basis, scope, confidence, freshness and reassessment.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009" ] } ], "artifacts": [ { "id": "assurance-level-basis-scope-confidence-freshness-and-reassessment-record", "name": "Assurance level, basis, scope, confidence, freshness and reassessment record", "description": "Versioned evidence-bearing registry record for assurance level, basis, scope, confidence, freshness and reassessment with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus assurance-level-basis-scope-confidence-freshness-and-reassessment assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "quality-rule-validation-result-conflict-contest-and-redress", "name": "Quality rule, validation result, conflict, contest and redress", "description": "Rule and version, result and errors, conflicting assertions, reporter, subject contest, redress case, resolution authority and preserved outcome.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-011" ], "questions": [ { "id": "quality-rule-validation-result-conflict-contest-and-redress-q01", "text": "What identifiers, authorities, classes, versions, scope and values define quality rule, validation result, conflict, contest and redress?", "kind": "requirement", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "quality-rule-validation-result-conflict-contest-and-redress-q02", "text": "Which source, evidence, event time, effective time and knowledge time support quality rule, validation result, conflict, contest and redress?", "kind": "decision", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "quality-rule-validation-result-conflict-contest-and-redress-q03", "text": "How may quality rule, validation result, conflict, contest and redress be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "exception", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "quality-rule-validation-result-conflict-contest-and-redress-data", "name": "Quality rule, validation result, conflict, contest and redress data", "description": "Structured identity-register data for quality rule, validation result, conflict, contest and redress.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "quality-rule-validation-result-conflict-contest-and-redress-record", "name": "Quality rule, validation result, conflict, contest and redress record", "description": "Versioned evidence-bearing registry record for quality rule, validation result, conflict, contest and redress with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus quality-rule-validation-result-conflict-contest-and-redress assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-resolution-and-entity-resolution", "name": "Lifecycle, resolution and entity resolution", "description": "Maintains durable identity through change and provides safe, attributable lookup.", "rationale": "Current state is derived from immutable events; similarity is not identity and merge is never silent.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-011" ], "layers": [ { "id": "entry-and-binding-lifecycle", "name": "Entry and binding lifecycle", "description": "Separates entry continuity from each identifier binding and external subject lifecycle.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009" ], "findings": [ { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events", "name": "Register, activate, suspend, reactivate, revoke, retire and expire events", "description": "Typed event, target entry or binding, prior and next state, authority, reason, effective time, observation time, reversibility and evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009" ], "questions": [ { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events-q01", "text": "What identifiers, authorities, classes, versions, scope and values define register, activate, suspend, reactivate, revoke, retire and expire events?", "kind": "ownership", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events-q02", "text": "Which source, evidence, event time, effective time and knowledge time support register, activate, suspend, reactivate, revoke, retire and expire events?", "kind": "provenance", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events-q03", "text": "How may register, activate, suspend, reactivate, revoke, retire and expire events be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "privacy", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events-data", "name": "Register, activate, suspend, reactivate, revoke, retire and expire events data", "description": "Structured identity-register data for register, activate, suspend, reactivate, revoke, retire and expire events.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "register-activate-suspend-reactivate-revoke-retire-and-expire-events-record", "name": "Register, activate, suspend, reactivate, revoke, retire and expire events record", "description": "Versioned evidence-bearing registry record for register, activate, suspend, reactivate, revoke, retire and expire events with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus register-activate-suspend-reactivate-revoke-retire-and-expire-events assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "correction-supersession-tombstone-redirect-and-non-reuse", "name": "Correction, supersession, tombstone, redirect and non-reuse", "description": "Non-destructive correction, successor relation, tombstone and redirect response, identifier quarantine or non-reuse and retained minimum evidence.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-011" ], "questions": [ { "id": "correction-supersession-tombstone-redirect-and-non-reuse-q01", "text": "What identifiers, authorities, classes, versions, scope and values define correction, supersession, tombstone, redirect and non-reuse?", "kind": "classification", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "correction-supersession-tombstone-redirect-and-non-reuse-q02", "text": "Which source, evidence, event time, effective time and knowledge time support correction, supersession, tombstone, redirect and non-reuse?", "kind": "quality", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "correction-supersession-tombstone-redirect-and-non-reuse-q03", "text": "How may correction, supersession, tombstone, redirect and non-reuse be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "security", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "correction-supersession-tombstone-redirect-and-non-reuse-data", "name": "Correction, supersession, tombstone, redirect and non-reuse data", "description": "Structured identity-register data for correction, supersession, tombstone, redirect and non-reuse.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "correction-supersession-tombstone-redirect-and-non-reuse-record", "name": "Correction, supersession, tombstone, redirect and non-reuse record", "description": "Versioned evidence-bearing registry record for correction, supersession, tombstone, redirect and non-reuse with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus correction-supersession-tombstone-redirect-and-non-reuse assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "matching-deduplication-merge-split-and-resolution", "name": "Matching, deduplication, merge, split and resolution", "description": "Records entity-resolution claims and lookup outcomes without hiding uncertainty.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-006", "SRC-011" ], "findings": [ { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review", "name": "Candidate match, features, method, score, threshold and authority review", "description": "Candidate entries, privacy-safe features, matching method and version, score and scale, threshold, uncertainty, reviewer and disposition.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ], "questions": [ { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review-q01", "text": "What identifiers, authorities, classes, versions, scope and values define candidate match, features, method, score, threshold and authority review?", "kind": "composition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review-q02", "text": "Which source, evidence, event time, effective time and knowledge time support candidate match, features, method, score, threshold and authority review?", "kind": "measurement", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review-q03", "text": "How may candidate match, features, method, score, threshold and authority review be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review-data", "name": "Candidate match, features, method, score, threshold and authority review data", "description": "Structured identity-register data for candidate match, features, method, score, threshold and authority review.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "candidate-match-features-method-score-threshold-and-human-or-authority-review-record", "name": "Candidate match, features, method, score, threshold and authority review record", "description": "Versioned evidence-bearing registry record for candidate match, features, method, score, threshold and authority review with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus candidate-match-features-method-score-threshold-and-human-or-authority-review assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result", "name": "Equivalence, relatedness, merge, split, survivor, lineage and resolution result", "description": "Typed same-subject or related assertion, evidence and authority, merge survivor, split children, lineage, redirect and scoped resolver result.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006", "SRC-011" ], "questions": [ { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result-q01", "text": "What identifiers, authorities, classes, versions, scope and values define equivalence, relatedness, merge, split, survivor, lineage and resolution result?", "kind": "state", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result-q02", "text": "Which source, evidence, event time, effective time and knowledge time support equivalence, relatedness, merge, split, survivor, lineage and resolution result?", "kind": "lifecycle", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result-q03", "text": "How may equivalence, relatedness, merge, split, survivor, lineage and resolution result be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "retention", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result-data", "name": "Equivalence, relatedness, merge, split, survivor, lineage and resolution result data", "description": "Structured identity-register data for equivalence, relatedness, merge, split, survivor, lineage and resolution result.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result-record", "name": "Equivalence, relatedness, merge, split, survivor, lineage and resolution result record", "description": "Versioned evidence-bearing registry record for equivalence, relatedness, merge, split, survivor, lineage and resolution result with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus equivalence-relatedness-merge-split-survivor-lineage-and-resolution-result assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "federation-mapping-interoperability-and-projections", "name": "Federation, mapping, interoperability and projections", "description": "Connects registers while preserving authority, ambiguity and information loss.", "rationale": "A mapping is a scoped assertion between identifiers or entries, not proof that two entire profiles are equal.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-010", "SRC-011" ], "layers": [ { "id": "cross-register-federation-and-mapping", "name": "Cross-register federation and mapping", "description": "Pins remote authority, trust and matching semantics for every link.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-011" ], "findings": [ { "id": "federation-participant-trust-policy-namespace-and-resolution-contract", "name": "Federation participant, trust policy, namespace and resolution contract", "description": "Remote register and operator, trust and acceptance policy, supported namespaces, resolver endpoint, authentication, freshness and failure behavior.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "federation-participant-trust-policy-namespace-and-resolution-contract-q01", "text": "What identifiers, authorities, classes, versions, scope and values define federation participant, trust policy, namespace and resolution contract?", "kind": "identity", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "federation-participant-trust-policy-namespace-and-resolution-contract-q02", "text": "Which source, evidence, event time, effective time and knowledge time support federation participant, trust policy, namespace and resolution contract?", "kind": "evidence", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "federation-participant-trust-policy-namespace-and-resolution-contract-q03", "text": "How may federation participant, trust policy, namespace and resolution contract be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "federation-participant-trust-policy-namespace-and-resolution-contract-data", "name": "Federation participant, trust policy, namespace and resolution contract data", "description": "Structured identity-register data for federation participant, trust policy, namespace and resolution contract.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "federation-participant-trust-policy-namespace-and-resolution-contract-record", "name": "Federation participant, trust policy, namespace and resolution contract record", "description": "Versioned evidence-bearing registry record for federation participant, trust policy, namespace and resolution contract with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus federation-participant-trust-policy-namespace-and-resolution-contract assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict", "name": "Cross-register mapping, relation, scope, confidence, validity and conflict", "description": "Local and remote entries or identifiers, relation type, mapping authority, scope, method, confidence, valid interval, conflict and revocation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ], "questions": [ { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict-q01", "text": "What identifiers, authorities, classes, versions, scope and values define cross-register mapping, relation, scope, confidence, validity and conflict?", "kind": "definition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict-q02", "text": "Which source, evidence, event time, effective time and knowledge time support cross-register mapping, relation, scope, confidence, validity and conflict?", "kind": "authority", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict-q03", "text": "How may cross-register mapping, relation, scope, confidence, validity and conflict be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "interoperability", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict-data", "name": "Cross-register mapping, relation, scope, confidence, validity and conflict data", "description": "Structured identity-register data for cross-register mapping, relation, scope, confidence, validity and conflict.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "artifacts": [ { "id": "cross-register-mapping-relation-scope-confidence-validity-and-conflict-record", "name": "Cross-register mapping, relation, scope, confidence, validity and conflict record", "description": "Versioned evidence-bearing registry record for cross-register mapping, relation, scope, confidence, validity and conflict with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus cross-register-mapping-relation-scope-confidence-validity-and-conflict assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "standard-crosswalk-and-purpose-bound-views", "name": "Standard crosswalk and purpose-bound views", "description": "Publishes interoperable projections without overstating equivalence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-010", "SRC-011" ], "findings": [ { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting", "name": "ISO, NIST, DID, CID, VC, GS1 and LEI crosswalk and loss accounting", "description": "Source and target profile versions, mapped concepts and fields, normalization, omissions, collisions, semantic conflicts and round-trip classification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010", "SRC-011" ], "questions": [ { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting-q01", "text": "What identifiers, authorities, classes, versions, scope and values define iso, nist, did, cid, vc, gs1 and lei crosswalk and loss accounting?", "kind": "relationship", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting-q02", "text": "Which source, evidence, event time, effective time and knowledge time support iso, nist, did, cid, vc, gs1 and lei crosswalk and loss accounting?", "kind": "temporal", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting-q03", "text": "How may iso, nist, did, cid, vc, gs1 and lei crosswalk and loss accounting be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "access", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting-data", "name": "ISO, NIST, DID, CID, VC, GS1 and LEI crosswalk and loss accounting data", "description": "Structured identity-register data for iso, nist, did, cid, vc, gs1 and lei crosswalk and loss accounting.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010", "SRC-011" ] } ], "artifacts": [ { "id": "iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting-record", "name": "ISO, NIST, DID, CID, VC, GS1 and LEI crosswalk and loss accounting record", "description": "Versioned evidence-bearing registry record for iso, nist, did, cid, vc, gs1 and lei crosswalk and loss accounting with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus iso-nist-did-cid-vc-gs1-lei-crosswalk-and-loss-accounting assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "public-relying-party-registrar-subject-self-and-analytical-projection", "name": "Public, relying-party, registrar, subject-self and analytical projection", "description": "Audience, purpose, legal or policy authority, included fields, redactions, pseudonymization, freshness, expiry and disclosure event.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005" ], "questions": [ { "id": "public-relying-party-registrar-subject-self-and-analytical-projection-q01", "text": "What identifiers, authorities, classes, versions, scope and values define public, relying-party, registrar, subject-self and analytical projection?", "kind": "requirement", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "public-relying-party-registrar-subject-self-and-analytical-projection-q02", "text": "Which source, evidence, event time, effective time and knowledge time support public, relying-party, registrar, subject-self and analytical projection?", "kind": "decision", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "public-relying-party-registrar-subject-self-and-analytical-projection-q03", "text": "How may public, relying-party, registrar, subject-self and analytical projection be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "exception", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "public-relying-party-registrar-subject-self-and-analytical-projection-data", "name": "Public, relying-party, registrar, subject-self and analytical projection data", "description": "Structured identity-register data for public, relying-party, registrar, subject-self and analytical projection.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "public-relying-party-registrar-subject-self-and-analytical-projection-record", "name": "Public, relying-party, registrar, subject-self and analytical projection record", "description": "Versioned evidence-bearing registry record for public, relying-party, registrar, subject-self and analytical projection with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus public-relying-party-registrar-subject-self-and-analytical-projection assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "rights-privacy-access-retention-and-agent-governance", "name": "Rights, privacy, access, retention and agent governance", "description": "Controls identity data and autonomous change across its full lifetime.", "rationale": "Identity registers create correlation and exclusion risk, so access, redress, retention and agent authority are first-class semantics.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ], "layers": [ { "id": "purpose-access-privacy-and-subject-rights", "name": "Purpose, access, privacy and subject rights", "description": "Makes every use and disclosure accountable and contestable.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log", "name": "Purpose, legal basis, consent, access grant, exception and disclosure log", "description": "Purpose and authority, consent or alternative basis, actor and role, allowed bundle or finding, conditions, expiry, exception and minimum disclosure receipt.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log-q01", "text": "What identifiers, authorities, classes, versions, scope and values define purpose, legal basis, consent, access grant, exception and disclosure log?", "kind": "ownership", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log-q02", "text": "Which source, evidence, event time, effective time and knowledge time support purpose, legal basis, consent, access grant, exception and disclosure log?", "kind": "provenance", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log-q03", "text": "How may purpose, legal basis, consent, access grant, exception and disclosure log be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "privacy", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log-data", "name": "Purpose, legal basis, consent, access grant, exception and disclosure log data", "description": "Structured identity-register data for purpose, legal basis, consent, access grant, exception and disclosure log.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "purpose-legal-basis-consent-access-grant-exception-and-disclosure-log-record", "name": "Purpose, legal basis, consent, access grant, exception and disclosure log record", "description": "Versioned evidence-bearing registry record for purpose, legal basis, consent, access grant, exception and disclosure log with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus purpose-legal-basis-consent-access-grant-exception-and-disclosure-log assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress", "name": "Subject notice, access, correction, objection, restriction, portability and redress", "description": "Applicable right, subject or representative, request, identity verification method, deadline, decision, remedy, appeal and protected evidence.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress-q01", "text": "What identifiers, authorities, classes, versions, scope and values define subject notice, access, correction, objection, restriction, portability and redress?", "kind": "classification", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress-q02", "text": "Which source, evidence, event time, effective time and knowledge time support subject notice, access, correction, objection, restriction, portability and redress?", "kind": "quality", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress-q03", "text": "How may subject notice, access, correction, objection, restriction, portability and redress be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "security", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress-data", "name": "Subject notice, access, correction, objection, restriction, portability and redress data", "description": "Structured identity-register data for subject notice, access, correction, objection, restriction, portability and redress.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "subject-notice-access-correction-objection-restriction-portability-and-redress-record", "name": "Subject notice, access, correction, objection, restriction, portability and redress record", "description": "Versioned evidence-bearing registry record for subject notice, access, correction, objection, restriction, portability and redress with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus subject-notice-access-correction-objection-restriction-portability-and-redress assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "retention-audit-and-safe-agent-operations", "name": "Retention, audit and safe agent operations", "description": "Prevents autonomous maintenance from rewriting identity history or crossing authority boundaries.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-009" ], "findings": [ { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary", "name": "Retention class, legal hold, disposition, tombstone and erasure boundary", "description": "Record class, retention trigger and duration, legal hold, disposition authority, fields removed, tombstone minimum and proof of completion.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-009" ], "questions": [ { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary-q01", "text": "What identifiers, authorities, classes, versions, scope and values define retention class, legal hold, disposition, tombstone and erasure boundary?", "kind": "composition", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary-q02", "text": "Which source, evidence, event time, effective time and knowledge time support retention class, legal hold, disposition, tombstone and erasure boundary?", "kind": "measurement", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary-q03", "text": "How may retention class, legal hold, disposition, tombstone and erasure boundary be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "validation", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary-data", "name": "Retention class, legal hold, disposition, tombstone and erasure boundary data", "description": "Structured identity-register data for retention class, legal hold, disposition, tombstone and erasure boundary.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "retention-class-legal-hold-disposition-tombstone-and-erasure-boundary-record", "name": "Retention class, legal hold, disposition, tombstone and erasure boundary record", "description": "Versioned evidence-bearing registry record for retention class, legal hold, disposition, tombstone and erasure boundary with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus retention-class-legal-hold-disposition-tombstone-and-erasure-boundary assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit", "name": "Agent authority, operation, idempotency, concurrency, validation, rollback and audit", "description": "Agent and delegation, operation, purpose, expected head, idempotency key, pre-write checks, result, post-write checks, recovery and audit event.", "source_refs": [ "SRC-002", "SRC-006", "SRC-009" ], "questions": [ { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit-q01", "text": "What identifiers, authorities, classes, versions, scope and values define agent authority, operation, idempotency, concurrency, validation, rollback and audit?", "kind": "state", "answer_data": [ "identifiers and authorities", "classes and profiles", "versions and scope", "values and explicit unknowns" ] }, { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit-q02", "text": "Which source, evidence, event time, effective time and knowledge time support agent authority, operation, idempotency, concurrency, validation, rollback and audit?", "kind": "lifecycle", "answer_data": [ "source and authority", "evidence and method", "event and effective time", "observation and knowledge time", "confidence and assumptions" ] }, { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit-q03", "text": "How may agent authority, operation, idempotency, concurrency, validation, rollback and audit be validated, contested, corrected, superseded, retained and disclosed without silent merging or expanding authority?", "kind": "retention", "answer_data": [ "validation", "contest and redress", "successor history", "retention and access", "authority boundary" ] } ], "data_elements": [ { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit-data", "name": "Agent authority, operation, idempotency, concurrency, validation, rollback and audit data", "description": "Structured identity-register data for agent authority, operation, idempotency, concurrency, validation, rollback and audit.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit-record", "name": "Agent authority, operation, idempotency, concurrency, validation, rollback and audit record", "description": "Versioned evidence-bearing registry record for agent authority, operation, idempotency, concurrency, validation, rollback and audit with authority, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical identity-register assertion", "source evidence, event or validation reference" ], "serial": true, "identity_strategy": "Register-qualified entry identifier plus agent-authority-operation-idempotency-concurrency-validation-rollback-and-audit assertion or event identifier; subject name, identifier value, timestamp and digest never identify the entry alone.", "source_refs": [ "SRC-002", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "establish-register-and-namespace", "name": "Establish register and namespace", "description": "Create the governed register profile, authority, subject scope, identifier scheme and resolution rules.", "inputs": [ "Dimension policy", "operator authority", "subject scope", "scheme profile" ], "outputs": [ "register-profile revision" ], "preconditions": [ "mandate, namespace, scheme syntax, uniqueness and steward validate" ], "effects": [ "a versioned identifier space becomes available without creating subject entries" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-010", "SRC-011" ] }, { "id": "register-subject-anchor", "name": "Register subject anchor", "description": "Create a minimal entry that references an external subject master under evidenced registrar authority.", "inputs": [ "register profile", "subject reference", "registration evidence" ], "outputs": [ "identity-entry revision" ], "preconditions": [ "subject kind, registrar, evidence, duplicate check, privacy and expected head validate" ], "effects": [ "one durable anchor is created and registration provenance is appended" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] }, { "id": "assign-or-bind-identifier", "name": "Assign or bind identifier", "description": "Mint or bind a scheme-governed identifier to an existing entry with explicit validity and source.", "inputs": [ "entry", "identifier scheme", "assignment authority", "evidence" ], "outputs": [ "identifier-binding revision" ], "preconditions": [ "syntax, canonical form, uniqueness, non-reuse, authority and evidence validate" ], "effects": [ "a source-qualified identifier binding becomes resolvable" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-007", "SRC-008", "SRC-010" ] }, { "id": "resolve-identifier-purpose-bound", "name": "Resolve identifier purpose-bound", "description": "Resolve an identifier to the minimum permitted current projection while preserving ambiguity and source state.", "inputs": [ "identifier", "purpose", "requester", "freshness requirement" ], "outputs": [ "resolution result or structured error" ], "preconditions": [ "scheme, access, status, redirect, ambiguity, freshness and rate policy validate" ], "effects": [ "an attributable result is returned without asserting authentication or authorization" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-010" ] }, { "id": "attach-evidence-and-assess-assurance", "name": "Attach evidence and assess assurance", "description": "Append proofing, assignment or verification evidence and a scope-qualified assurance assessment.", "inputs": [ "entry or binding", "evidence reference", "method", "assessor" ], "outputs": [ "evidence assertion and assurance assessment" ], "preconditions": [ "source authority, integrity, custody, method version, scope, time and disclosure validate" ], "effects": [ "reliance basis and residual uncertainty become explicit" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] }, { "id": "record-match-or-equivalence-assertion", "name": "Record match or equivalence assertion", "description": "Record candidate similarity, same-subject, related or not-same decisions without changing entry identity.", "inputs": [ "candidate entries", "method", "features", "authority" ], "outputs": [ "entity-resolution assertion" ], "preconditions": [ "privacy, method version, score scale, threshold, evidence, review and relation type validate" ], "effects": [ "identity-resolution evidence is visible and contestable" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-011" ] }, { "id": "merge-split-correct-or-supersede", "name": "Merge, split, correct or supersede", "description": "Apply an authorized, evidenced lineage change while preserving prior entries, identifiers and redirects.", "inputs": [ "affected entries", "change authority", "reason", "successor plan" ], "outputs": [ "successor revisions, lineage event and tombstones" ], "preconditions": [ "expected heads, evidence, contest status, survivor or children, non-reuse and rollback validate" ], "effects": [ "current resolution changes without erasing identity history" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-009", "SRC-011" ] }, { "id": "suspend-revoke-retire-or-reactivate", "name": "Suspend, revoke, retire or reactivate", "description": "Append a status transition to an entry or binding with reason, authority and effective time.", "inputs": [ "entry or binding", "transition", "authority", "evidence" ], "outputs": [ "lifecycle event and derived state" ], "preconditions": [ "transition guard, authority, reason, effective time, notifications and reversibility validate" ], "effects": [ "current standing changes while prior state and evidence remain" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "federate-map-and-project", "name": "Federate, map and project", "description": "Create a scoped cross-register mapping or standards projection with explicit trust and loss accounting.", "inputs": [ "local revision", "remote register or target profile", "purpose", "mapping evidence" ], "outputs": [ "federation mapping or projection" ], "preconditions": [ "versions, relation semantics, authority, confidence, disclosure, omissions and round trip validate" ], "effects": [ "another system receives a traceable, loss-aware representation" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-010", "SRC-011" ] }, { "id": "exercise-rights-retain-dispose-and-audit", "name": "Exercise rights, retain, dispose and audit", "description": "Process correction or redress and authorized retention or disposition without destroying required lineage.", "inputs": [ "entry", "request or retention trigger", "authority", "policy" ], "outputs": [ "rights decision, disposition event or audit evidence" ], "preconditions": [ "requester verification, authority, deadline, legal hold, minimum tombstone and post-write checks validate" ], "effects": [ "rights and records duties are fulfilled with attributable evidence" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-006", "SRC-009" ] } ], "composition": [ { "target": "Person, Organization, Device, Service and Thing models", "relation": "REFERENCE", "purpose": "Resolve the subject without copying its profile or lifecycle.", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011" ] }, { "target": "Credential, Account, Authentication, Key, Policy and Source Document models", "relation": "REFERENCE", "purpose": "Use external proof, control and decision evidence while preserving responsibility boundaries.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005" ] }, { "target": "ISO/IEC 24760-1 and NIST SP 800-63-4", "relation": "ALIGN", "purpose": "Align identity vocabulary, proofing, assurance, federation, risk, privacy and redress concepts.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "DID Core, Controlled Identifiers and Verifiable Credentials", "relation": "ALIGN", "purpose": "Project controlled identifiers, controller and resolution data and credential evidence without universalizing their trust model.", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "target": "GS1 Digital Link and GLEIF LEI formats", "relation": "ALIGN", "purpose": "Support product, asset, location and legal-entity identifier profiles with explicit scope and loss accounting.", "required": false, "source_refs": [ "SRC-010", "SRC-011" ] }, { "target": "PROV-O, RFC 3986, RFC 9562 and RFC 3339", "relation": "ALIGN", "purpose": "Represent provenance, identifiers, local UUIDs and explicit event times.", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-009" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, registrar, namespace authority and accountable privacy and records stewards", "Identity-register, subject-kind, identifier-scheme, evidence-method, assurance, federation, rights and retention registries", "Master-system mappings for persons, organizations, devices, things, services, credentials, accounts, keys, source documents, policies and audit logs", "Registration, uniqueness, non-reuse, entity-resolution, lifecycle, disclosure, federation, redress, retention and agent-operation policies" ], "namespace_guidance": "Mint a Dimension identifier for each register and register-qualified entry. Retain authoritative external subject and scheme identifiers. Never use a name, identifier value, timestamp or digest alone as universal subject identity.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local register, namespace, scheme, assurance, evidence-method, federation and rights registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize an entry by register identifier plus entry identifier; canonicalize identifier bindings under their named scheme and version, not by display label or ad hoc string normalization.", "Canonical representation, comparison, uniqueness scope, persistence and reassignment rules are versioned and cited by every binding." ], "patch_rules": [ "Extensions declare subject domain, authority, identifier scheme, target finding, required evidence, lifecycle, privacy, interoperability and migration impact.", "Changes to namespace meaning, comparison, uniqueness, non-reuse, authoritative scope, equivalence, merge or resolution behavior require a successor profile, migration map and preserved old resolver semantics." ], "compatibility_rules": [ "Unknown additive fields may be ignored only when entry identity, subject reference, identifier binding, authority, status, time, provenance, access and lineage remain intact.", "Every ISO, NIST, DID, CID, VC, GS1 or LEI mapping pins source and target versions and states omissions, collisions, semantic conflicts and round-trip limits." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system register and entry identifiers qualified by namespace and operator.", "Governed globally resolvable URI or sector identifier under a named scheme authority.", "Dimension UUID under RFC 9562 when no external or governed global identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate request, registration, assignment, effective, observation, ingestion, correction, resolution and knowledge times.", "serial_naming_rule": "Use {register-id}--{scope-id}--{artifact-kind}--{assertion-or-event-id}, where scope-id is register for register-scoped records or the entry identifier for entry-scoped records; never use subject name, identifier value, date or digest alone.", "integrity_rule": "Store digest, media type, register and optional entry binding, assertion or event identity, scheme and profile versions, event and knowledge times, authority, access marking and provenance." }, "policies": [ "An identity register anchors identifiers and source-qualified identity assertions; it does not own the subject profile, credential, account, authentication factor, key, authorization decision or business lifecycle.", "Identifier equality, name similarity, matching score, credential validity and successful lookup do not alone prove subject equality, control, authentication, authorization or current eligibility.", "Duplicate candidates, conflicts, corrections, merges, splits, supersession and retirement are append-only, evidenced and contestable; no silent collapse or identifier reuse is permitted.", "Agents may perform allowlisted reversible registration, validation and projection operations, but high-impact merges, splits, revocations, rights denials and destructive disposition require delegated authority and policy-defined confirmation." ], "crud": { "read": [ "Resolve Dimension policy, register profile, scheme version, access purpose, entry head, status, redirects, assurance freshness and source-qualified conflicts before use." ], "create": [ "Create register identity and policy, then entry identity, external subject reference, registrar evidence and duplicate assessment before assigning identifiers." ], "update": [ "Append identifier, evidence, status, match, correction, merge, split, rights or federation events with actor, authority, reason, event and knowledge time and provenance; never overwrite cited history." ], "delete": [ "Apply rights, retention, legal hold and audit policy; remove eligible personal data only through authorized disposition while retaining the minimum lawful tombstone, non-reuse marker, lineage and evidence of action." ] }, "roles": [ { "name": "Register owner and namespace authority", "responsibilities": [ "Own mandate, authoritative scope, identifier scheme, uniqueness and resolution contract." ] }, { "name": "Registrar and evidence verifier", "responsibilities": [ "Create entries and bindings only under approved evidence and proofing rules." ] }, { "name": "Subject or authorized representative", "responsibilities": [ "Receive notice and exercise applicable access, correction, objection and redress rights." ] }, { "name": "Identity-resolution steward", "responsibilities": [ "Review duplicates, conflicts, matches, merges and splits and preserve lineage." ] }, { "name": "Federation and interoperability steward", "responsibilities": [ "Govern cross-register trust, mappings, profile versions and loss accounting." ] }, { "name": "Privacy, security and records steward", "responsibilities": [ "Control minimization, disclosure, redress, retention, legal hold, disposition and auditability." ] }, { "name": "Relying party", "responsibilities": [ "Interpret scoped resolution and assurance evidence under external policy without treating it as universal truth." ] } ], "access": { "default_rule": "Deny proofing evidence, sensitive identifiers, private aliases, match features, conflicts, subject-rights records and unrestricted correlation handles; grant only the minimum current fields required by an authorized purpose.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Registrar, subject-self, auditor, regulator, incident-response or court access cites authority and remains purpose-bound, minimum-necessary, attributable, time-limited and separately logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, register and entry, operation, policy, RFC 3339 time, affected assertions, source revision and outcome without copying protected evidence into the log." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension identity, register, namespace, privacy, rights, retention, federation and agent-operation policies.", "Read this pattern and linked subject, credential, account, key, policy, source-document and audit models before mutation." ] } }, "coverage": { "claim": "Covers a single-provider, source-grounded identity-register model spanning register authority and namespace rules, entry anchoring and external subject reference, identifier and alias bindings, registration and assignment evidence, assurance and quality, entry and binding lifecycle, matching, merge, split and resolution, cross-register federation and standards crosswalks, and purpose, rights, access, retention and agent governance across 6 bundles, 12 layers, 24 findings, 24 artifacts and 10 functions over 11 sources. This is not universal completeness: relationship rows are unapproved composition proposals, the composition, relationships, spatial and interoperability dimensions are self-declared gaps, ISO/IEC 24760-1 is represented at catalogue level only, question kinds are mechanically rotated rather than semantically assigned, and biometric matching, civil and population registries, eIDAS wallets, sanctions screening and sector eligibility are explicitly excluded and require separate specialist profiles.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Register, entry, subject reference, identifier binding, evidence assertion and lifecycle event identities are distinct." }, { "dimension": "classification and definition", "status": "covered", "notes": "Subject kinds, register profiles, identifier schemes, match relations and assurance frameworks are versioned." }, { "dimension": "direct properties", "status": "covered", "notes": "Namespace, identifiers, status, authority, assurance, matching, lineage, resolution and rights are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Parsing, canonicalization, uniqueness, proofing, validation, source observation and confidence are covered." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Establish, register, bind, resolve, evidence, match, merge, split, transition, federate and dispose are governed." }, { "dimension": "composition", "status": "gap", "notes": "Subject profiles, credentials, accounts, keys, policies, source documents and audit logs remain external masters." }, { "dimension": "lifecycle", "status": "covered", "notes": "Registration, activation, suspension, revocation, expiry, correction, merge, split, supersession and retirement preserve history." }, { "dimension": "relationships", "status": "gap", "notes": "Entry-subject, binding-entry, evidence-assertion, same-subject, related, predecessor, successor and federation links are typed." }, { "dimension": "temporal", "status": "covered", "notes": "Request, event, effective, observation, ingestion, resolution and knowledge times remain distinct." }, { "dimension": "spatial", "status": "gap", "notes": "Jurisdiction, operator location and subject location are referenced only when material and source-qualified." }, { "dimension": "provenance", "status": "covered", "notes": "Registration, assignment, proofing, matching, lifecycle, resolution and disclosure retain responsible-agent provenance." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Register, namespace, subject, credential, key, policy, rights and records responsibilities are separated." }, { "dimension": "validation and quality", "status": "covered", "notes": "Syntax, canonical form, uniqueness, evidence, status, duplicate, stale-head, mapping and privacy checks are explicit." }, { "dimension": "access and privacy", "status": "covered", "notes": "Minimal projections, correlation controls, purpose, subject rights and deny-by-default evidence are explicit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Legal hold, disposition, erasure boundary, tombstone, redirect, non-reuse and audit evidence are covered." }, { "dimension": "interoperability", "status": "gap", "notes": "ISO, NIST, DID, CID, VC, URI, UUID, GS1 and LEI alignments are versioned and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; later identity, privacy and jurisdictional review is required before canonical promotion.", "No approved relation rows were supplied; relationships to person, organization, device, credential, authentication, authorization, master-data and audit models remain composition proposals.", "Biometric matching, national civil identity, population registers, eIDAS wallets, sector-specific eligibility and sanctions screening require separate specialist profiles.", "ISO/IEC 24760-1 is represented from the official public catalogue and sample metadata, not a licensed full-text conformity assessment." ], "conflicts": [ "An identifier may be unique within one namespace yet collide or be reused under another authority or time interval.", "Two entries may be similar or linked without being legally or operationally equivalent, while one subject can legitimately have multiple identities across contexts.", "Privacy minimization, fraud detection, subject access, public transparency, archival duties and non-reuse can impose competing retention and disclosure requirements." ], "regional_assumptions": [ "Legal identity, identifier validity, subject rights, proofing evidence, retention and redress depend on jurisdiction and sector.", "NIST guidance primarily addresses persons using online services and does not establish a universal person, device or thing register.", "GS1 and GLEIF define domain identifier systems; their authority and semantics must not be generalized beyond their registered subjects and rules." ], "adversarial_checks": [ "Reject an entry whose register, namespace, subject reference, registrar authority or current revision cannot be resolved.", "Reject identifier equality or match score represented as conclusive subject equality without relation type, evidence, scope and authority.", "Reject silent merge, split, correction, reassignment or deletion that loses predecessor, successor, redirect, tombstone or provenance.", "Reject a resolution result represented as authentication, authorization, legal identity or eligibility by itself.", "Reject an agent operation that crosses Dimension authority, broadens disclosure, skips duplicate checks or destroys evidence under hold." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "registry", "status": "reclassified", "rationale": "Two axes must be kept apart. On the record plane, the frozen registry value classifies how the model record itself is packaged and published (for example a standalone model-registry entry under vr.wm-xct-016); that is a cataloguing label about the artifact and is never a valid subject-model entry kind. On the subject plane, the modeled thing is a governed identity register that owns an aggregate root, a mandate and jurisdiction, a namespace and scheme authority, register-qualified entry identity, append-only lifecycle events, a resolution contract, federation mappings and a retention regime; the schema enum provides `registry` for exactly that shape. Codex declared `pattern`, which under-specifies ownership: `pattern` properly names reusable structures that carry no owned aggregate root or independent lifecycle and are composed into some other root, and asserting it here invites consumers to embed register state inside person, organization, device, service or thing masters, contradicting the model's own firewall that the register must not import subject master data. Instantiability across many subject kinds is a packaging and reuse property, not a subject-kind property, so it does not justify collapsing the two axes. Reclassify the subject-model kind to `registry`, normalize the purpose wording away from 'registry pattern', and state plainly in every published artifact that `registry` here names the modeled identity register and not the Vercy model-record registry plane." }, "decisions": [ { "concept": "Entry kind declared as `pattern`", "disposition": "rejected - reclassified to `registry`", "rationale": "The model owns an aggregate root, mandate, namespace authority, entry identity, lifecycle events and resolution contract, which is the `registry` shape; `pattern` under-specifies ownership and invites embedding register state into subject masters." }, { "concept": "Aggregate root: register as outer root with register-qualified entry as sub-root", "disposition": "accepted", "rationale": "The dual identity strategy is internally consistent: register-scoped records omit an entry segment while entry-scoped records are register-qualified, and the {register-id}--{scope-id}--{artifact-kind}--{assertion-or-event-id} serial rule encodes that hierarchy without ambiguity." }, { "concept": "Ownership firewall against subject master data, credentials, accounts, keys and authorization decisions", "disposition": "accepted", "rationale": "Five boundary notes carry source references, and the load-bearing policy that identifier equality, name similarity, match score, credential validity and successful lookup never alone prove subject equality, control, authentication, authorization or eligibility is the correct constraint for a register." }, { "concept": "Scope statement claiming the register owns subject rights, access and retention", "disposition": "rejected in part - narrow to request handling and evidence", "rationale": "Subject rights are conferred by jurisdiction and law and belong to external legal and policy models; the register owns the request, verification method, deadline, decision, remedy and redress evidence. The service layer also places access and retention policy at the Dimension level, so unqualified 'owns' overstates the boundary." }, { "concept": "Composition relations to person, organization, device, credential, account, key, authorization, master-data and audit models", "disposition": "deferred", "rationale": "No approved relation rows were supplied, so these must be published as typed composition proposals and visibly labelled as such rather than presented as contracted relations that downstream consumers can bind against." }, { "concept": "Coverage checklist `gap` entries whose notes read as coverage statements", "disposition": "rejected as written - deferred to editorial correction", "rationale": "Relationships, composition, spatial and interoperability are all marked `gap` while their notes assert that links are typed, masters are external, location is source-qualified and alignments are versioned and loss-aware; the status and note contradict each other and misrepresent what is actually missing." }, { "concept": "Uniform primary_source=true and authority_tier=1 across all eleven sources", "disposition": "rejected in part", "rationale": "The ISO catalogue page and the GLEIF supporting-documents landing page are access points rather than normative texts, so a flat tier-1 primary-source claim lets catalogue metadata carry the weight of specification clauses; tier and primary-source flags must be qualified per source." }, { "concept": "SRC-001 ISO/IEC 24760-1:2025 as the core identity-concept anchor", "disposition": "accepted with constraint", "rationale": "Admissible as a terminology and authority anchor given the declared catalogue-level representation, but no normative clause-level requirement may be attributed to it in any finding or crosswalk until licensed full text is checked against the cited assertions." }, { "concept": "Recency-sensitive pins SRC-010 (GS1 Digital Link 1.7.0, ratified August 2026) and SRC-011 (GLEIF, accessed 6 September 2026)", "disposition": "deferred to live verification", "rationale": "A no-tools audit cannot confirm ratification status, release numbering or the current common-data-file versions, and an 'accessed' date is not a version pin; both must be re-fetched and pinned before canonical promotion." }, { "concept": "Templated question text with positionally rotated question kinds", "disposition": "rejected - rework required", "rationale": "All 24 findings reuse three identical stems and the 24 kind labels cycle in a fixed eight-finding rotation, so kinds such as `relationship`, `state` and `measurement` sit on definitional or evidentiary text; taxonomy coverage is mechanical rather than semantic and overstates interrogation depth." }, { "concept": "Artifact identity strategy and serial naming rule", "disposition": "accepted with clarification", "rationale": "Refusing subject name, identifier value, timestamp or digest as sole identity is exactly correct for an identity register, but the model must state that the model-internal `*-record` artifact slugs are not instance serials and must enumerate the permitted `artifact-kind` values referenced by the naming rule." }, { "concept": "Retention: append-only lineage, tombstone minimum, non-reuse marker and erasure boundary", "disposition": "accepted with constraint", "rationale": "The tension between erasure rights and non-reuse and lineage duties is honestly declared as a conflict, but 'minimum lawful tombstone' is undefined; a named tombstone-content profile must guarantee retained markers are not re-identifying correlation handles." }, { "concept": "Access scopes bundle, layer, finding and artifact with deny-by-default evidence", "disposition": "accepted with constraint", "rationale": "Artifact is the finest declared scope, yet every artifact mixes a logical assertion with source evidence and validation references, so artifact-level scoping cannot enforce the stated minimum-necessary field disclosure without a field-level redaction profile." }, { "concept": "Function set of ten operations against the declared canon and patch rules", "disposition": "accepted for this pass - one gap recorded", "rationale": "The canon rules mandate successor profiles, migration maps and preserved old resolver semantics when namespace meaning, uniqueness, non-reuse or equivalence change, but no function performs scheme or profile version supersession; add_functions must remain empty under the waiver, so this is recorded rather than patched." }, { "concept": "`merge-split-correct-or-supersede` bundling four high-impact operations", "disposition": "deferred", "rationale": "Policy requires delegated authority and policy-defined confirmation for merges, splits and revocations, and bundling correction and supersession alongside them coarsens the granularity at which that authority can be delegated, gated and audited." }, { "concept": "Service layers under the owner-authorized second-provider waiver", "disposition": "accepted unchanged", "rationale": "merge_service_layers stays true only for schema compatibility; with no second provider there is nothing to merge, so the codex dimension, canon and patch, artifact, policy, CRUD, role, access and bootstrap layers pass through verbatim without synthesizer modification." } ], "publicationHolds": [ "Live source and version verification hold: all eleven URLs must be re-fetched and pinned before canonical promotion, with specific attention to SRC-001 (ISO/IEC 24760-1:2025 edition 3, currently represented from catalogue and sample metadata only), SRC-010 (GS1 Digital Link URI Syntax release 1.7.0 and its claimed August 2026 ratification) and SRC-011 (GLEIF common data file supporting documents, cited only by an access date rather than a version).", "Absence-of-independent-review hold: the repository owner authorized completion with Claude and Grok waived, so this result carries no second-provider corroboration and no external adversarial review. Every publication artifact must display the waiver, the recorded reasons and the reviewable-draft status, and must not be represented as cross-provider validated.", "Entry-kind reclassification hold: publication must carry the corrected subject-model kind `registry` in place of `pattern`, and must state both axes explicitly so the record-plane classification of the model artifact is never read as the subject-model entry kind.", "Unapproved-relations hold: relationships to person, organization, device, service, thing, credential, account, key, authorization, master-data and audit-log models must be published as composition proposals with a visible label, since no approved relation rows exist and the coverage checklist contradicts itself on this point.", "Research-quality caveat hold: the artifact must disclose that all 24 findings share three templated question stems and that question-kind labels are assigned by a fixed rotation rather than by meaning, so taxonomy coverage counts must not be cited as evidence of interrogation depth.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Licensed full-text clause-level conformity check of ISO/IEC 24760-1:2025 edition 3 against every finding and crosswalk assertion that currently cites SRC-001, replacing catalogue-level attribution with clause-level attribution.", "Obtain approved relation rows binding this register to the person, organization, device, service, thing, credential, authentication, authorization, master-data and audit-log models, converting the current composition proposals into contracted, typed relations.", "Add a scheme and profile supersession function covering successor profiles, migration maps and preserved old resolver semantics, since the canon and patch rules mandate that behavior but no current function performs it.", "Define a field-level redaction and disclosure profile below artifact scope, so deny-by-default minimization can be enforced where a single artifact mixes assertion content with proofing evidence, match features and validation references.", "Define a named tombstone-content profile fixing the minimum lawful retained fields after disposition, and prove that non-reuse markers and lineage remnants are not re-identifying correlation handles.", "Resolve and document the relationship between W3C Controlled Identifiers v1.0 (SRC-003) and DID Core v1.0 (SRC-004) inside the crosswalk finding, including which controller-document semantics are superseded and what round-trip loss that implies.", "Re-derive question kinds semantically per finding and diversify question text, replacing the current fixed eight-finding rotation of the 24-kind taxonomy across three cycles.", "Commission the excluded specialist profiles for biometric matching, national civil identity and population registers, eIDAS wallets, sanctions screening and sector-specific eligibility before any of those uses are claimed as in scope." ] }, "statistics": { "sources": 11, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }